Printing device
Summary by NHIP
Remote Authentication Printing
The method transmits unique authentication data from a printing device or its installed print cartridge to a remotely connected client computer. The data is embedded within a web page hyperlink that enables the client to authenticate itself to a server.
Claim Score by NHIP
Abstract
A printing device can transmit authentication data to a client computer remotely connected to the printing device. The authentication data can be used by the client computer to authenticate itself to a server computer.

Term
0.8 yearsleft in the term
Expires 18 July 2027, including 999 days of term adjustment.
- Priority and filed
- Granted
- Today
- Expires
44 claims: 10 independent, 34 dependent
- 1A method comprising:transmitting, by a printing device, authentication data that uniquely identifies at least one of the printing device or a print cartridge installed therein to a client computer remotely connected to the printing device, wherein the authentication data is transmitted to the client computer as a web page including a hyperlink having the authentication data embedded therein;and wherein the authentication data can be used by the client computer to authenticate itself to a server computer.
- 9A method comprising:transmitting, by a printing device, a web page to a client computer remotely connected to the printing device, the web page including a hyperlink having embedded authentication data usable by the client computer to authenticate itself to a server computer;wherein the client computer displays the web page;wherein a selection of the hyperlink causes the client computer to transmit a request to the server computer;and wherein the request includes the authentication data.
- 11A printing device including a printing mechanism, comprising:a control system configured to transmit a web page including a hyperlink having authentication data embedded therein to a first computer, wherein the hyperlink points to a resource provided by the second computer, and wherein the first computer can use the authentication data to authenticate itself to a second computer and to demonstrate authority to access the resource.
- 16A printing device, comprising:means for receiving a request from a client computer remotely connected to the printing device;means for responding to the request by transmitting authentication data to the client computer, the authentication data including at least one of a cartridge identifier that uniquely identifies a print cartridge installed in the printing device or a printer identifier that uniquely identifies the printing device;wherein the authentication data is transmitted to the client computer as a web page including a hyperlink having the authentication data embedded therein;wherein the authentication data enables the client computer to authenticate itself to a particular server computer;and wherein the server computer is remotely connected to the client computer.
- 20A print cartridge for use in a printing device, comprising:(a) a supply of print material;and (b) a memory;wherein the memory stores authentication data for use by a client computer to demonstrate to a particular server computer that the client computer is an authorized party, wherein the authentication data is transmitted to the client computer as a web page including a hyperlink having the authentication data embedded therein, and wherein the authentication data includes an identifier that uniquely identifies the print cartridge.
- 27In a client computer, a method of requesting access to a resource, comprising:receiving, from a printing device, a web page including a hyperlink having embedded authentication data associated with the resource;transmitting a request to access the resource;and wherein the request includes the authentication data received from the printing device.
- 39In a server computer, a method comprising:receiving from a client computer a request for a resource, wherein the request includes authentication data;using the authentication data to determine if the client computer is an authorized party;wherein the client computer obtained the authentication data from a printing device;and wherein the authentication data includes a printer identifier uniquely identifying the printing device and a cartridge identifier uniquely identifying a print cartridge that is presently installed in the printing device, wherein, for each granted request for the resource, a message history record including the cartridge identifier and the printer identifier is stored in a database, and wherein the using the authentication data to determine if the client computer is an authorized party includes: searching the database to locate all message history records having the cartridge identifier of the request;and determining whether the number of unique printer identifiers in the located message history records exceeds a predetermined value.
- 42One or more computer-readable storage devices containing computer-executable instructions that, when executed by a printing device, perform the following steps:reading authentication data from a memory;and transmitting the authentication data to a remote computer connected to the printing device as a web page including a hyperlink having the authentication data embedded therein;wherein the remote computer uses the authentication data to authenticate itself to a remote computer.
- 43In a printing device, a method comprising:receiving, in the printing device, a challenge block from a client computer, wherein the challenge block is generated by a server computer in response to a request from the client computer to the server computer and transmitted by the server computer to the client computer;in response to the receiving, generating a response block in the printing device using a private key obtained from a consumable component installed in the printing device;transmitting the response block to the client computer;and wherein the client computer uses the response block to authenticate itself to a server computer.
- 44Broadest claimClaim Score 87, broad(NHIP)A method comprising:transmitting, by a printing device, authentication data to a client computer remotely connected to the printing device as a web page including a hyperlink having the authentication data embedded therein;and wherein the authentication data can be used by the client computer to authenticate itself to a server computer.
Independent claims10
105 paragraphs in 4 sections, as filed
BACKGROUND OF THE INVENTION
p-0002As used herein, the phrase “printing device” refers to any device that includes a printing function. Thus, for example, the phrase “printing device” may refer to an inkjet printer, a laser printer, a commercial printing press, a multifunction peripheral (MFP) that includes a printing function, etc.
p-0003Many types of printing devices are equipped with replaceable components each having a life cycle during which the replaceable component is functional. At the end of the life cycle of a replaceable component, the component is often replaced for the printing device to continue to function properly.
p-0004For example, a print cartridge is installed in many types of printing devices to provide a supply of print material (e.g., toner or ink) for the printing process. As documents are printed, the print material is gradually depleted. When the supply of print material is exhausted, or when some other part in the print cartridge wears out, the print cartridge is typically replaced. A user who wishes to obtain a replacement component, such as a print cartridge, for a printing device may purchase the component from a supplier.
p-0005New and innovative ways are needed to enable a printing device component supplier and/or a printing device manufacturer to provide valuable services and/or information to their customers.
BRIEF DESCRIPTION OF THE DRAWINGS
p-0006<figref idrefs="DRAWINGS">FIG. 1A</figref> is a high level block diagram of a computing system;
p-0007<figref idrefs="DRAWINGS">FIG. 1B</figref> illustrates an authentication protocol followed by a server;
p-0008<figref idrefs="DRAWINGS">FIG. 1C</figref> illustrates authentication data that is in accordance with the authentication protocol;
p-0009<figref idrefs="DRAWINGS">FIG. 1D-1E</figref> show a flow diagram illustrating how a supplier may configure a print cartridge with authentication data;
p-0010<figref idrefs="DRAWINGS">FIG. 2A</figref> illustrates a print cartridge that is installed in the printing device;
p-0011<figref idrefs="DRAWINGS">FIG. 2B</figref> illustrates the data that may be stored in a memory of the print cartridge;
p-0012<figref idrefs="DRAWINGS">FIG. 3</figref> is a high level block diagram a printing device;
p-0013<figref idrefs="DRAWINGS">FIG. 4</figref> is a high-level block diagram of a server computer;
p-0014<figref idrefs="DRAWINGS">FIG. 5A</figref> is a flow diagram illustrating how a client computer may interact with a printing device;
p-0015<figref idrefs="DRAWINGS">FIG. 5B</figref> is a flow diagram illustrating how a server computer may respond to a request for a resource;
p-0016<figref idrefs="DRAWINGS">FIG. 6</figref> is a flow diagram illustrating how a client device may obtain authentication data from a printing device;
p-0017<figref idrefs="DRAWINGS">FIG. 7</figref> is a flow diagram illustrating how a printing device may provide authentication data to a client device; and
p-0018<figref idrefs="DRAWINGS">FIG. 8</figref> is a high-level block diagram of a computing system.
DETAILED DESCRIPTION OF THE INVENTION
p-0019As used herein, the phrase “authentication data” refers to data that can be sent from a first computer to a second computer in order to demonstrate to the second computer that the first computer is an “authorized party”. An “authorized party” refers to a computing device that has certain authority or privileges. Typically, authentication data is in accordance with a pre-determined authentication protocol.
p-0020Shown in <figref idrefs="DRAWINGS">FIG. 1A</figref> is a computing system <b>102</b> that is in accordance with an example embodiment of the invention. The computing system <b>102</b> includes a client computer <b>104</b> and a printing device <b>106</b>. The client computer <b>104</b> is capable of communicating with the printing device <b>106</b> over a local communication link <b>108</b>. The local communication link <b>108</b> may represent a communication cable, a wireless communication path, a network, etc.
p-0021The client computer <b>104</b> is also capable of communicating over the Public Internet <b>110</b>. In some implementations, for example, the client computer <b>104</b> connects to the Public Internet <b>110</b> via a firewall.
p-0022The client computer <b>104</b> may be any type of computing device that allows a user <b>112</b> to interactively browse Web pages. In the present embodiment, the client computer <b>104</b> runs a Web Browser application <b>114</b> and includes a display <b>116</b>, a central processing unit (CPU) <b>118</b>, and various user input devices <b>120</b>. The user input devices <b>120</b> may include a keyboard and/or a computer mouse. In specific implementations, the client computer <b>104</b> may represent a desk-top computer, a workstation, a lap-top computer, a personal digital assistant (PDA), a cell phone that permits Web Browsing, etc.
p-0023The printing device <b>106</b> may be any type of printing device that uses a replaceable component. In the present embodiment, for example, the printing device <b>106</b> is a laser printing device. Installed in the printing device <b>106</b> is a replaceable print cartridge <b>122</b> that provides a supply of toner for the printing process.
p-0024We will assume in the following discussion that the user <b>112</b> has purchased (or otherwise acquired) the print cartridge <b>122</b> from a particular component supplier <b>124</b>. Thus, the user <b>112</b> is a customer of the component supplier <b>124</b>.
p-0025As indicated in <figref idrefs="DRAWINGS">FIG. 1A</figref>, the component supplier <b>124</b> maintains a server computer <b>126</b> on the Public Internet <b>110</b> in order to provide a resource <b>128</b> for the benefit of its customers. In the present embodiment, the resource <b>128</b> can be requested using a version of the Hypertext transfer protocol (HTTP) and is assigned a unique Uniform Resource Locator (URL) address.
p-0026It is noted that the resource <b>128</b> may represent a routine (or routines) that the server computer <b>126</b> can perform in response to a client request and/or a file (or files) that the server computer <b>126</b> can deliver to a client in response to a client request. In some implementations, for example, the resource <b>128</b> provides a client with content that a customer of the supplier <b>124</b> might consider of value. Such content may be in the form of text, digital images, artwork, animation, streaming multimedia video and/or streaming audio, for example.
p-0027In this respect and in specific implementations, the resource <b>128</b> may represent a Web page, or some other type of file, that includes content a customer of the supplier <b>124</b> may value. In other specific implementations, the resource <b>128</b> may represent a multi-media video that includes content a customer may value.
p-0028Of course the possibilities of what type of content could be delivered by the server computer <b>126</b> in response to a client request for the resource <b>128</b> are nearly endless. Therefore, the actual content that is delivered in various embodiments of the invention can vary quite significantly. By way of example, according to one implementation the content is an educational online course that may be of interest to a customer and that can be delivered by the server computer <b>126</b> to a client computer via streaming multimedia video. According to another implementation, the content is a library of images (e.g., unique clip art) that may be of interest to a customer.
h-0004General Overview of Authentication Scheme
p-0029As indicated in <figref idrefs="DRAWINGS">FIG. 1B</figref>, the server computer <b>126</b> implements an authentication protocol <b>130</b> in order to control access to the resource <b>128</b>. In accordance with this protocol, a client computer (e.g., client computer “A”) transmits authentication data to the server computer <b>126</b> in order to demonstrate authority to access the resource <b>128</b>. In this embodiment, the authentication data is specified by parameters that are included in a request for the resource <b>128</b>.
p-0030As shown in <figref idrefs="DRAWINGS">FIG. 1C</figref>, authentication data (e.g., authentication data <b>136</b>) that is in accordance with the authentication protocol <b>130</b> can be logically divided into a first and a second set of data. The first set of data is obtained from a memory of a print cartridge that is provided by the component supplier <b>124</b>. For ease of discussion, we may refer to this first set of data as “cartridge authentication data”. The cartridge authentication data, in the present embodiment, describes a secret number and a unique identifier (cartridge identifier) that can identify the print cartridge. The second set of data is a unique identifier (printer identifier) that identifies the printing device presently using the print cartridge.
p-0031Thus, for example, the authentication data <b>136</b> shown in <figref idrefs="DRAWINGS">FIG. 1C</figref> includes cartridge authentication data <b>138</b> and a printer identifier <b>140</b>. The cartridge authentication data <b>136</b> describes a secret number <b>142</b> and a cartridge identifier <b>144</b>. The cartridge identifier <b>144</b> identifies the particular cartridge that presently stores the cartridge authentication data <b>138</b>. The printer identifier <b>142</b> identifies the particular printing device that is presently using the print cartridge.
p-0032Shown in <figref idrefs="DRAWINGS">FIGS. 1D and 1E</figref> is a flow diagram illustrating generally how the component supplier <b>124</b> provides its customers with the ability to access the resource <b>128</b>.
p-0033At step <b>150</b>, a print cartridge that includes a memory is selected by the component supplier <b>124</b>. At step <b>152</b>, a secret number is generated. In the present embodiment, this step is performed at the direction of the component supplier <b>124</b> or by a third party that the component supplier <b>124</b> trusts. In specific implementations, for example, the secret number may be a randomly generated number and/or a large number (e.g., a number greater than 2000 bits) that would be hard for an un-trusted third party to guess.
p-0034At step <b>154</b>, a unique identifier is generated that can identify the selected print cartridge.
p-0035At step <b>156</b>, the secret number and the print cartridge identifier is stored in the memory of the selected print cartridge.
p-0036At step <b>158</b>, a record of the cartridge authentication data (i.e., the secret number and the print cartridge identifier) is stored in an internal memory of the server computer <b>126</b>.
p-0037At step <b>160</b>, the print cartridge (now configured with cartridge authentication data) is provided to a customer of the component supplier <b>124</b>.
p-0038At step <b>162</b>, the customer installs the print cartridge in his/her printing device.
p-0039At step <b>164</b>, the printing device passes authentication data to a client computer. The authentication data is in accordance with the authentication protocol <b>130</b> and includes the cartridge authentication data and a printer identifier that identifies the printing device. In this example embodiment and as discussed further below, the printing device performs this step by providing the client with a web page that includes a hyperlink to the resource <b>128</b>. The authentication data is included in the hyperlink.
p-0040At step <b>166</b>, the client computer receives the authentication data from the printing device and then transmits a request for the resource <b>128</b> to the server computer <b>126</b>. The request includes the authentication data received from the printing device.
p-0041At step <b>168</b>, the server computer <b>126</b> receives the authentication data and uses this data to determine if the client computer has the authority to access the resource <b>128</b>. In part, this step is accomplished by verifying that the server computer <b>126</b> has a record of the cartridge authentication data that is included with the authentication data.
h-0005Print Cartridge Construction
p-0042<figref idrefs="DRAWINGS">FIG. 2A</figref> illustrates the print cartridge <b>122</b> that is installed in the printing device <b>106</b>. As shown, the print cartridge <b>122</b> includes a housing <b>202</b> that contains a supply of toner material <b>204</b>. The print cartridge <b>122</b> further includes a non-volatile memory <b>208</b> that is in an integrated part of the print cartridge <b>122</b>. In this example, the print cartridge memory <b>208</b> is permanently attached to an outer surface of the print cartridge housing <b>202</b> as shown.
p-0043It is noted that in some specific implementations, for example, the print cartridge memory <b>208</b> is of a type that can be accessed over a wireless communication link. In these implementations the print cartridge memory <b>208</b> may represent a radio frequency identification (RFID) tag, for example. In other implementations, the memory <b>208</b> may be of a type that can be accessed via a hard-wired connection.
p-0044As shown in <figref idrefs="DRAWINGS">FIG. 2B</figref>, the print cartridge memory <b>208</b> stores cartridge authentication data <b>220</b> that is in accordance with the authentication protocol <b>130</b>. The cartridge authentication data <b>220</b> includes a secret number <b>222</b> and a cartridge identifier <b>224</b> (e.g., a serial number) that identifies the print cartridge <b>122</b>. As discussed further below, the server computer <b>126</b> maintains a record of the cartridge authentication data <b>220</b>.
h-0006Printing Device Construction
p-0045<figref idrefs="DRAWINGS">FIG. 3</figref> is a high level block diagram illustrating one example of how the printing device <b>106</b> may be constructed in accordance with an embodiment of the invention. <figref idrefs="DRAWINGS">FIG. 3</figref> shows the printing device <b>106</b> with the print cartridge <b>122</b> installed.
p-0046As shown in <figref idrefs="DRAWINGS">FIG. 3</figref>, the printing device <b>106</b> may include an Input-output (I/O) port <b>302</b>, a memory <b>304</b> and a processor <b>306</b>. The printing device <b>106</b> may further include a printing mechanism <b>308</b> and a cartridge memory communication interface <b>310</b>.
p-0047The I/O port <b>302</b> is generally any hardware, firmware, or gate level logic enabling the printing device <b>106</b> to communicate with the client computer <b>104</b> over the communication link <b>108</b>.
p-0048The memory <b>304</b> is generally any memory device or set of memory devices enabling the printing device <b>106</b> to store certain information. In this embodiment, for example, the memory <b>304</b> stores printer control firmware <b>320</b> that the processor <b>306</b> can execute. The memory <b>304</b> also stores a printer identifier <b>324</b>, the URL address <b>326</b> that is assigned to the resource <b>128</b> and a printer Web Page <b>328</b>. The printer identifier <b>324</b> may represent a unique serial number assigned to the printing device <b>106</b>.
p-0049The printing mechanism <b>308</b> enables the printing device <b>106</b> to controllably place marks on a print media. As previously noted, in this embodiment, the printing device is a laser printer. The printing mechanism <b>308</b> may therefore include a photoconductor and an exposure system for controllably exposing the photoconductor so as to create a latent image. During printing, the printing mechanism <b>308</b> uses toner (that can be obtained from the installed print cartridge <b>122</b>) to develop the latent image. The developed latent image may then be transferred (directly or indirectly) to a print media so as to generate printed output.
p-0050The cartridge memory communication interface <b>310</b> enables the printing device <b>106</b> to read the cartridge authentication data <b>220</b> from the print cartridge memory <b>208</b> when the print cartridge <b>122</b> is installed. In implementations wherein the cartridge memory <b>208</b> can be accessed wirelessly, the cartridge communication interface <b>310</b> may include circuitry that enables the printing device to access the print cartridge memory <b>208</b> over a wireless communication link. If, however, the cartridge memory <b>208</b> is accessible via a hard-wired connection the cartridge communication interface <b>310</b> may include circuitry that temporarily establishes a hard-wired connection with the print cartridge memory <b>208</b> while the print cartridge <b>122</b> is installed in the printing device <b>106</b>.
h-0007Server Computer Construction
p-0051<figref idrefs="DRAWINGS">FIG. 4</figref> is a high-level block diagram illustrating one example of how the server computer <b>126</b> may be constructed in accordance with an embodiment of the invention. As shown in <figref idrefs="DRAWINGS">FIG. 4</figref>, the server computer <b>126</b> may include an input-output (I/O) port <b>402</b>, a memory <b>404</b> and a processor <b>406</b>.
p-0052The I/O port <b>402</b> is generally any hardware, firmware, or gate level logic enabling the server computer <b>126</b> to communicate over the Public Internet <b>110</b>. In some implementations, the I/O port <b>402</b> enables the server computer <b>126</b> to be connected to a local intranet system that is interconnected to the Public Internet <b>110</b> via a firewall.
p-0053The memory <b>404</b> is generally any memory device or set of memory devices enabling the server computer <b>126</b> to store a server software module <b>408</b>, a record <b>410</b> and a □message history□database <b>412</b>. The record <b>410</b> specifies the cartridge authentication data <b>220</b> that is stored the print cartridge memory <b>208</b>.
p-0054The message history database <b>412</b> maintains a record of certain information that was included in previously received requests for the resource <b>128</b>. As noted above, authentication data that is accordance with the authentication protocol <b>130</b> includes a secret number, a cartridge identifier, and a printer identifier. When a request (for the resource <b>128</b>) that includes this information is received, the server computer <b>126</b> may place a record in the message history database <b>412</b>. The record specifies the cartridge identifier as well as the printer identifier that is included with the request. As will be discussed further below, this information may subsequently be used to detect the scenario wherein the cartridge authentication data is being distributed in an unauthorized way.
p-0055The processor <b>406</b> is generally any processor device or set of processor devices that can execute the software module <b>408</b>. The software module <b>408</b> enables the server computer <b>126</b> to provide the resource <b>128</b> as well as to maintain the message history database <b>412</b>.
h-0008Operation of Printing Device and Client Computer
p-0056<figref idrefs="DRAWINGS">FIG. 5A</figref> is a flow diagram illustrating generally how the client computer <b>104</b>, while executing the Web Browser <b>114</b>, may interact with the printing device <b>106</b> to obtain authentication data for transmission to the server computer <b>126</b>. <figref idrefs="DRAWINGS">FIG. 5A</figref> further shows how the client computer <b>104</b> can then use this information to authenticate itself to the server computer <b>126</b> in accordance with the authentication protocol <b>130</b>.
p-0057Beginning at step <b>504</b>, we assume the user <b>112</b> interacts with the client computer <b>104</b> to input a user request to retrieve the printer Web Page <b>328</b>. This step may involve the user <b>112</b> inputting a URL address assigned to the printer Web page <b>328</b>.
p-0058At step <b>506</b>, the client computer <b>104</b> responds to the user request by transmitting an electronic request for the printer Web Page <b>328</b> over the communication link <b>108</b>.
p-0059At step <b>508</b>, the printing device <b>106</b> receives the request and in response thereto performs steps <b>510</b>-<b>518</b>. The printing device <b>106</b> may automatically perform these steps at the direction of the printer control firmware <b>320</b>.
p-0060At step <b>510</b>, the printing device <b>106</b> reads the cartridge authentication data <b>220</b> from the print cartridge memory <b>208</b>. At step <b>512</b>, the printing device <b>106</b> reads the printer identifier <b>324</b> and the URL address <b>326</b> (of the resource <b>128</b>) from the printer memory <b>304</b>.
p-0061At step <b>514</b>, the printing device <b>106</b> uses the information obtained at step <b>510</b>-<b>512</b> to define a hyperlink. The hyperlink is formatted so that, when selected, a request for the resource <b>128</b> is transmitted to the server computer <b>126</b>. The request includes authentication data that is in accordance with the authentication protocol <b>130</b>. The authentication data may, for example, be in the form of parameters that specify the cartridge authentication data <b>220</b> and the printer identifier <b>324</b>. The authentication data may alternatively be passed to the server as hidden fields in a form.
p-0062At step <b>516</b>, the printing device <b>106</b> inserts the hyperlink into the Web page <b>328</b>. At step <b>518</b>, the printing device <b>106</b> transmits the Web page <b>328</b> (now modified to include the hyperlink) to the client computer <b>104</b>. At step <b>520</b>, the client computer <b>104</b> receives the modified Web Page <b>328</b> and displays it to the user <b>112</b>.
p-0063At step <b>522</b>, the user <b>112</b> further interacts with the client computer <b>104</b> to select the hyperlink included with the Web page <b>328</b>. In response to the hyperlink being selected, the client computer <b>104</b> operates to transmit a request for the resource <b>128</b> to the Server computer <b>126</b> (step <b>524</b>). The request includes parameters that specify the cartridge authentication data <b>220</b> and the printer identifier <b>324</b>.
h-0009Operation of Server System
p-0064<figref idrefs="DRAWINGS">FIG. 5B</figref> shows a flow diagram illustrating one way the server computer <b>126</b> may operate upon receiving the current request (i.e., the request transmitted at step <b>524</b>) for the resource <b>128</b>. The server computer <b>126</b> may automatically perform these steps at the direction of the server software <b>408</b>.
p-0065At step <b>530</b>, the server computer <b>126</b> receives the request for the resource <b>128</b>. In response to the request, the server computer <b>126</b> initiates an authentication routine to determine if the originator of the request (i.e., the client computer <b>104</b>) is an authorized party and is therefore entitled to access the resource <b>128</b> (step <b>532</b>). One embodiment of the authentication routine is illustrated by steps <b>534</b>-<b>540</b>.
p-0066At step <b>534</b>, the server computer <b>126</b> determines if the current request for the resource <b>128</b> include parameters that specify cartridge authentication data and a printer identifier in accordance with the authentication protocol <b>130</b>. If these parameters are not included in the request, the server computer <b>126</b> determines that the party that transmitted the request is not an authorized party and the request for the resource <b>128</b> is denied (step <b>536</b>). If, however, the request does include these parameters the server computer <b>126</b> proceeds to step <b>538</b>. <ul><li id="ul0001-0001" num="0000"><ul><li id="ul0002-0001" num="0066">In this example, the current request includes parameters that specify the cartridge authentication data <b>220</b> and the printer identifier <b>324</b>. This is in accordance with the authentication protocol <b>130</b>. Therefore, the server computer <b>126</b> proceeds to step <b>538</b>.</li></ul></li></ul>
p-0067At step <b>538</b>, the server computer <b>126</b> determines if it has a record of the cartridge authentication data that is included in the request. If no such record exists, then the request for the resource <b>128</b> is denied (step <b>536</b>). If, however, such a record does exist, the server computer <b>126</b> proceeds to step <b>540</b>. <ul><li id="ul0003-0001" num="0000"><ul><li id="ul0004-0001" num="0068">In this example, the current request includes the cartridge authentication data <b>220</b>. Furthermore, the server computer <b>126</b> includes a record (i.e., the record <b>410</b>) of this data. Thus, the server computer <b>126</b> proceeds to step <b>540</b>.</li></ul></li></ul>
p-0068At step <b>540</b>, the server computer <b>126</b> uses the information included in the message history database <b>412</b> to determine if the cartridge authentication data included in the current request has been compromised.
p-0069If such a condition is detected, then the request for the resource <b>128</b> is denied (step <b>536</b>). If, however, such a condition is not detected then the originator of the request is determined to be an authorized party and access to the resource <b>128</b> permitted (step <b>542</b>). Thus if the resource <b>128</b> is a Web page, for example, the server computer <b>126</b> would transmit the Web page to the client computer <b>104</b> if the client computer <b>104</b> is determined to be an authorized party.
p-0070Before we discuss one specific way the server computer <b>126</b> could perform step <b>540</b>, it is instructive to first consider the following scenario. Suppose a third party has obtained, in an unauthorized way, a copy of the cartridge authentication data <b>220</b>. Suppose further this third party is widely distributing print cartridges that include a copy of the cartridge authentication data <b>220</b> and that each of these cartridges is installed in a different printing device that operate in a similar manner as the printing device <b>106</b>.
p-0071It can be seen that in the scenario just described, the server computer <b>126</b> may receive a number of requests for the resource <b>128</b> that specify a copy of the cartridge authentication data <b>220</b> but a different printer identifier.
p-0072Step <b>540</b> may be performed to detect this scenario and may be based upon an assumption that it would be unlikely a print cartridge (e.g., the print cartridge <b>122</b>) would be installed, over its lifetime, in more than “N_thresh” different printing devices. Thus, if the message history database <b>412</b> indicates that more than “N_thresh” different requests for the resource <b>128</b> have included the cartridge authentication data <b>220</b> but a uniquely different printer identifier, this would be an indication that the cartridge authentication data <b>220</b> has been copied and is being distributed in an unauthorized way. Put another way, this condition is an indication that the secret number <b>222</b> is no longer a secret.
p-0073Thus, for example, suppose five requests for the resource <b>128</b> had been previously received that included the cartridge authentication data <b>220</b>. The printer identifier specified by each of these requests is as follows: <ul><li id="ul0005-0001" num="0000"><ul><li id="ul0006-0001" num="0075">Previous Request #1 specified a printer identifier of “983543”;</li><li id="ul0006-0002" num="0076">Previous Request #2 specified a printer identifier of “983543”;</li><li id="ul0006-0003" num="0077">Previous Request #3 specified a printer identifier of “8452435”;</li><li id="ul0006-0004" num="0078">Previous Request #4 specified a printer identifier of “432345”;</li><li id="ul0006-0005" num="0079">Previous Request #5 specified a printer identifier of “983543”.</li></ul></li></ul>
p-0074In this example, N_unique=3 as there are three unique printer identifiers specified by the five previous requests. If N_thresh is set to 4, therefore, the current request for the resource <b>128</b> would be accepted as the value of “N_thresh” is greater than “N_unique”.
OTHER EXAMPLE EMBODIMENTS
p-0075<figref idrefs="DRAWINGS">FIG. 6</figref> is a flow diagram illustrating another embodiment of the invention. Referring now to <figref idrefs="DRAWINGS">FIG. 6</figref>, at step <b>602</b> a server computer is provided and connected to a network, such as the Public Internet. The server computer can provide a resource to authorized client devices.
p-0076At step <b>604</b>, a manufacturer manufactures a printing device component that includes a memory. The component may be any type of component that can be used in a printing device. In some specific implementations, the component may represent a replaceable component such as a replaceable print cartridge that contains toner or ink.
p-0077At step <b>606</b>, authentication data is generated that is in accordance with some pre-determined authentication protocol. At step <b>608</b>, the authentication data is stored in the memory of the printing device component.
p-0078At step <b>610</b>, the component is installed in a printing device. The printing device may be any type of printing device, such as an inkjet printing device or a laser printing device, for example. The printing device may even represent a commercial printer that uses liquid toner or liquid ink to print documents.
p-0079At step <b>612</b>, a client computer obtains the authentication data from the printing device. The client computer may obtain the authentication data from the printing device in any manner.
p-0080At step <b>614</b>, the client computer transmits the authentication data to the server computer in order to demonstrate it (i.e., the client computer) is an authorized party.
p-0081At step <b>616</b>, the server computer uses the authentication data to determine if the client computer is an authorized party.
p-0082<figref idrefs="DRAWINGS">FIG. 7</figref> is a flow diagram illustrating another embodiment of the invention. At step <b>702</b>, a printing device is provided authentication data (step <b>702</b>) that is in accordance with a pre-determined authentication protocol. The authentication data may be used by a client device to authenticate itself to a pre-identified server computer.
p-0083It is noted that step <b>702</b> may be performed by the manufacturer of the printing device. For example, the authentication data may be stored in a memory internal to the printing device prior to the printing device being provided to a customer.
p-0084At step <b>704</b>, the printing device transmits the authentication data to a client computer that is remotely attached to the printing device. The authentication data may be transmitted, for example, using a printer management language (e.g., PML, SNMP, various proprietary protocols, etc).
p-0085At step <b>706</b>, the client computer receives the authentication data. At step <b>708</b>, the client computer generates a graphical user interface (e.g., a Web page) that includes a hyperlink. This step may be performed at the direction of one or more software modules running on the client computer.
p-0086At step <b>710</b>, the client compute receives a selection of the hyperlink. The hyperlink is configured so that the selection at step <b>710</b> causes the client computer to transmit the authentication data to the pre-identified server computer.
p-0087At step <b>712</b>, the server computer receives the authentication data and uses this data to determine that the client computer is an authorized party.
p-0088In yet another embodiment, a challenge/response block authentication scheme is used. According to one implementation a client transmits a request to the server. In response to the request, the server generates a challenge block and transmits the challenge block back to the client. The client then passes the challenge block to the printing device.
p-0089When the printing device receives the challenge block from the client, it generates a response block using a private cryptographic key. The key may have been obtained by the printing device from a memory of print cartridge or some other component installed in the printing device.
p-0090After the response block is generated, the printing device passes the response block back the to the client device. The client device then forwards the response block on to the server in order to authenticate itself to the server.
p-0091The server receives the response block from the client and then processes the response block in order to verify the client is an authorized party.
p-0092Thus, in the example embodiment just described, the authentication data passed from the printing device to the client device and then to the server is a response block that is generated using a private key that the printing device possesses.
p-0093<figref idrefs="DRAWINGS">FIG. 8</figref> shows a computing system <b>802</b> that is in accordance with another example embodiment of the invention. The computing system <b>802</b> includes a printing device <b>804</b>, a client computer <b>806</b> and a server computer <b>808</b>.
p-0094The printing device <b>804</b> and the client computer <b>806</b> are connected via a first communication link <b>808</b>. The client computer <b>806</b> and the server computer <b>808</b> are connected via a second communication link <b>810</b>. The client computer <b>806</b> and the server computer <b>808</b> adhere to a pre-determined protocol <b>812</b> that defines how the client computer <b>806</b> can authenticate itself to the server computer <b>808</b>.
p-0095In accordance with the protocol <b>812</b>, the client computer <b>806</b> can pass data <b>814</b> to the server computer <b>808</b> in order to authenticate itself to the server computer <b>808</b>. As indicated in <figref idrefs="DRAWINGS">FIG. 8</figref>, the data <b>814</b> is obtained by the client computer <b>806</b> from the printing device <b>804</b>.
p-0096According to various implementations, the data <b>814</b> may be (or include) a unique identifier of a component that is presently installed in the printing device <b>804</b>. The data <b>814</b> may also be in an encrypted form.
p-0097In various implementations, for example, the data <b>814</b> may represent one or more encrypted numbers. For example, the data <b>814</b> may describe a first and a second number. The first number is an encrypted version of the second number. Upon receiving the data <b>814</b>, the server computer <b>808</b> may decrypt the first number and compare it to the second number. If the decrypted version of the first number matches the second number, the server computer <b>808</b> determines that the client computer <b>806</b> is an authorized party.
p-0098It is further noted that the present invention may be embodied in the form of a “computer-readable medium”. As used herein, the phrase “computer readable medium” can refer to any medium that can contain or store computer executable instructions. Thus, in this document, the phrase “computer-readable medium” may refer to a medium such as an optical storage device (e.g., a CD ROM) or a magnetic storage device (e.g., a magnetic tape).
p-0099Thus, a memory component (e.g., the server memory <b>404</b> or the printing device memory <b>304</b>) that stores computer executable instructions (e.g., the server software module <b>408</b> or the firmware module <b>324</b>) may represent an embodiment of the invention.
p-0100Although several embodiments of the invention have been described and illustrated, the invention is not to be limited to specific forms or arrangements of parts so described and illustrated. The invention is limited only by the claims and the equivalents thereof.
Contents4
15 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15
Every citation, both waysCites: the store holds 36 of 37
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US11221567B2 | Cited by | United States of America | Applicant |
| US11650518B2 | Cited by | United States of America | Applicant |
| US11027554B2 | Cited by | United States of America | Applicant |
| US2016207323A1 | Cited by | United States of America | Pre-grant |
| US11123994B2 | Cited by | United States of America | Applicant |
| US11020976B2 | Cited by | United States of America | Applicant |
| US11988978B2 | Cited by | United States of America | Applicant |
| US2019011853A1 | Cited by | United States of America | Pre-grant |
| US11067919B2 | Cited by | United States of America | Applicant |
| US2007124800A1 | Cited by | United States of America | Pre-grant |
| US10987936B2 | Cited by | United States of America | Applicant |
| US11014370B2 | Cited by | United States of America | Applicant |
| US8726370B2 | Cited by | United States of America | Search report |
| US10444667B2 | Cited by | United States of America | Applicant |
| US9882899B2 | Cited by | United States of America | Applicant |
| US10254681B2 | Cited by | United States of America | Search report |
| US10649369B2 | Cited by | United States of America | Applicant |
| US10101684B2 | Cited by | United States of America | Search report |
| US9914306B2 | Cited by | United States of America | Search report |
| US10191408B2 | Cited by | United States of America | Applicant |
| US11675289B2 | Cited by | United States of America | Applicant |
| US10386746B2 | Cited by | United States of America | Applicant |
| US2009038002A1 | Cited by | United States of America | Pre-grant |
| US11691429B2 | Cited by | United States of America | Applicant |
| US9561662B2 | Cited by | United States of America | Search report |
| US2016082740A1 | Cited by | United States of America | Pre-grant |
| US2002003634A1 | Cites | United States of America | Search report |
| US2002022990A1 | Cites | United States of America | Search report |
| US2002131784A1 | Cites | United States of America | Search report |
| US2002143893A1 | Cites | United States of America | Search report |
| US2002145636A1 | Cites | United States of America | Search report |
| US2002149785A1 | Cites | United States of America | Search report |
| US2002191217A1 | Cites | United States of America | Search report |
| US2003016382A1 | Cites | United States of America | Search report |
| US2003059050A1 | Cites | United States of America | Search report |
| US2003122891A1 | Cites | United States of America | Search report |
| US2004101320A1 | Cites | United States of America | Search report |
| US2004125165A1 | Cites | United States of America | Search report |
| US2005172118A1 | Cites | United States of America | Search report |
| US2006140647A1 | Cites | United States of America | Search report |
| US2006279588A1 | Cites | United States of America | Search report |
| US4670857A | Cites | United States of America | Search report |
| US5365312A | Cites | United States of America | Search report |
| US6094721A | Cites | United States of America | Search report |
| US6233409B1 | Cites | United States of America | Search report |
| US6302527B1 | Cites | United States of America | Search report |
| US6473191B2 | Cites | United States of America | Search report |
| US6625402B2 | Cites | United States of America | Search report |
| US6629134B2 | Cites | United States of America | Search report |
| US6672695B1 | Cites | United States of America | Search report |
| US6738903B1 | Cites | United States of America | Search report |
| US6863367B2 | Cites | United States of America | Search report |
| US7031012B1 | Cites | United States of America | Search report |
| US7044574B2 | Cites | United States of America | Search report |
| US7099028B2 | Cites | United States of America | Search report |
| US7130065B2 | Cites | United States of America | Search report |
| US7212637B2 | Cites | United States of America | Search report |
| US7240995B2 | Cites | United States of America | Search report |
| US7280772B2 | Cites | United States of America | Search report |
| US7324232B2 | Cites | United States of America | Search report |
| US7430053B2 | Cites | United States of America | Search report |
| US7460262B2 | Cites | United States of America | Search report |
| Jason Dyer, Lattice Reduction on Low-Exponent RSA, Aug. 2002, http://math.arizona.edu/~ura/022/McCallum-group/DyerFinal.pdf. | Non-patent | – | Search report |
2 members in 1 office
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 97139804 | United States of America | A | |
| US20040971398 | – | – | – |
Members2
| Document | Office | Kind | |
|---|---|---|---|
| US2006087678A1 | United States of America | A1 | |
| US7623255B2This record | United States of America | B2 |
48 transactions on the USPTO file
Allowed after 2 non-final rejections.
- Non-final rejections
- 2
- Final rejections
- 0
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Correspondence Address ChangeC.ADB | C.ADB | |
| Post Issue Communication - Certificate of CorrectionN423 | N423 | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTR | EML_NTR | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Examiner's AmendmentMEX.A | MEX.A | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Examiner's Amendment CommunicationEX.A | EX.A | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Withdraw Flagged for 5/25W525 | W525 | |
| Flagged for 5/25F525 | F525 | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| IFW TSS Processing by Tech Center CompleteTSSCOMP | TSSCOMP | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Application Return from OIPEWROIPE | WROIPE | |
| Application Return TO OIPEROIPE | ROIPE | |
| Application Is Now CompleteCOMP | COMP | |
| Application Return from OIPEWROIPE | WROIPE | |
| Application Return TO OIPEROIPE | ROIPE | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Application Is Now CompleteCOMP | COMP | |
| Cleared by L&R (LARS)L128 | L128 | |
| Referred to Level 2 (LARS) by OIPE CSRL198 | L198 | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Initial Exam Team nnIEXX | IEXX |
7 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Maintenance fee paymentMAFP | MAFP | |
| Fee paymentFPAY | FPAY | |
| Fee paymentFPAY | FPAY | |
| Certificate of correctionCC | CC | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS | |
| AssignmentAS | AS |
Numbers
- Publication, DOCDB
- 7623255
- Publication, EPODOC
- US7623255
- Application
- 10971398
- Application, DOCDB
- 97139804
- Application, EPODOC
- US20040971398
Titles
- English
- Printing device
Patent term adjustment
- A delay
- +999 daysthe office missed an examination deadline
- Net adjustment
- 999 days
Classification
- CPC, 1
- G06F21/34
- IPC, 1
- G06K15 02
- USPC, 8
- 358001150
- 347002000
- 358001160
- 380051000
- 399012000
- 399024000
- 399025000
- 713168000